Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2019-07-03 CVE-2019-12845 Improper Authentication vulnerability in Jetbrains Teamcity
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts.
network
low complexity
jetbrains CWE-287
5.0
2019-07-03 CVE-2019-12844 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages.
network
jetbrains CWE-94
4.3
2019-07-03 CVE-2019-12843 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection requiring a deliberate server administrator action was detected.
network
jetbrains CWE-94
4.3
2019-07-03 CVE-2019-12842 Cross-site Scripting vulnerability in Jetbrains Teamcity
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages.
network
jetbrains CWE-79
4.3
2019-07-03 CVE-2019-12841 Improper Input Validation vulnerability in Jetbrains Teamcity
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity.
network
low complexity
jetbrains CWE-20
5.0
2019-07-03 CVE-2019-10103 Missing Encryption of Sensitive Data vulnerability in Jetbrains Kotlin
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-311
8.1
2019-07-03 CVE-2019-10102 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Kotlin and Ktor
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-319
8.1
2019-07-03 CVE-2019-10101 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Kotlin
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-319
8.1
2019-07-03 CVE-2019-9873 Cleartext Storage of Sensitive Information vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
low complexity
jetbrains CWE-312
5.0
2019-07-03 CVE-2019-9872 Cleartext Storage of Sensitive Information vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
jetbrains CWE-312
4.3